CVSS2
Attack Vector
LOCAL
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:H/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
72.1%
Package : libgcrypt20
Version : 1.6.3-2+deb8u6
CVE ID : CVE-2019-13627
Debian Bug : #938938
It was discovered that there was a ECDSA timing attack in the
libgcrypt20 cryptographic library.
For Debian 8 "Jessie", this issue has been fixed in libgcrypt20 version
1.6.3-2+deb8u6.
We recommend that you upgrade your libgcrypt20 packages.
Regards,
,''`.
: :' : Chris Lamb
`. `'` [email protected] / chris-lamb.co.uk
`-
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 8 | all | libgcrypt11-dev | < 1.5.4-3+really1.6.3-2+deb8u8 | libgcrypt11-dev_1.5.4-3+really1.6.3-2+deb8u8_all.deb |
Debian | 8 | amd64 | libgcrypt20-dev | < 1.6.3-2+deb8u6 | libgcrypt20-dev_1.6.3-2+deb8u6_amd64.deb |
Debian | 8 | i386 | libgcrypt20-dev | < 1.6.3-2+deb8u8 | libgcrypt20-dev_1.6.3-2+deb8u8_i386.deb |
Debian | 8 | i386 | libgcrypt20-dbg | < 1.6.3-2+deb8u8 | libgcrypt20-dbg_1.6.3-2+deb8u8_i386.deb |
Debian | 8 | armhf | libgcrypt20-udeb | < 1.6.3-2+deb8u8 | libgcrypt20-udeb_1.6.3-2+deb8u8_armhf.deb |
Debian | 8 | amd64 | libgcrypt20 | < 1.6.3-2+deb8u8 | libgcrypt20_1.6.3-2+deb8u8_amd64.deb |
Debian | 8 | armel | libgcrypt20-dbg | < 1.6.3-2+deb8u8 | libgcrypt20-dbg_1.6.3-2+deb8u8_armel.deb |
Debian | 8 | all | libgcrypt20-doc | < 1.6.3-2+deb8u6 | libgcrypt20-doc_1.6.3-2+deb8u6_all.deb |
Debian | 8 | armhf | libgcrypt20-dev | < 1.6.3-2+deb8u8 | libgcrypt20-dev_1.6.3-2+deb8u8_armhf.deb |
Debian | 8 | amd64 | libgcrypt20-dbg | < 1.6.3-2+deb8u6 | libgcrypt20-dbg_1.6.3-2+deb8u6_amd64.deb |
CVSS2
Attack Vector
LOCAL
Attack Complexity
HIGH
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:L/AC:H/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
AI Score
Confidence
High
EPSS
Percentile
72.1%